1. Who is responsible for your data
The data controller is Tsupylo Vitalii, an individual developer established in Spain, operating under the brand KinPulse (“we”, “us”). Country of establishment: Spain. Website: kinpulse.app. Postal address: Av. Octavio Paz, 12, 264D, 29190 Málaga. For any question or request about personal data write to [email protected] with the subject “Privacy”. We are not required to appoint a Data Protection Officer; the same address is our privacy contact.
2. Scope and roles
This Policy covers: (a) users of the KinPulse App (iOS and Android); (b) people whose information is recorded in the App by a user, such as Care Recipients, family members and emergency contacts; (c) visitors of the Website; and (d) people who contact us by e-mail.
When a user records information about another person, the user decides what is recorded and with whom it is shared. We process that information on the user’s instructions and for the purposes described here. The user is responsible for having the right to record and share it and for informing the person concerned, where required (see “Information about other people”).
This Policy does not cover the Apple App Store, Google Play, your device’s operating system or other third-party services that have their own privacy policies.
3. Personal data we process
We process only the data needed to operate the Service. Your name, e-mail address and password are required to open an Account; without them we cannot provide the Service. All other data is optional and is processed only if you choose to use the related feature. Depending on how you use KinPulse the data includes:
- Account data: name, e-mail address, password (stored only as a salted cryptographic hash), interface language, time zone, optional profile photo, notification settings, care categories you enabled, selected plan and setup state, and, when you reset your password, a hashed reset code and the time of each reset request (kept for 24 hours).
- Care Data about you or your Care Recipients: name and relationship of each Care Recipient; medications (name, dose, unit, schedule, taken/skipped records); measurements such as blood pressure, blood sugar, weight, temperature, steps or sleep, and any custom measurement you add; well-being ratings; activities and therapies; doctor visits with date and notes; free-text notes; reminders. This is health data and may reveal other sensitive information (for example a therapy that implies a diagnosis).
- Family Space data: space name, members, roles, invitation codes, sharing grants, the author of each entry, and the onboarding answers given when the space was created (relationship, care mode, living distance, worries, medication frequency, health focus, care-circle size).
- SOS data: emergency contacts (name, phone number) saved for a Family Space; alerts with timestamp and status; one location reading (coordinates and accuracy) captured when an alert is sent, if you granted permission; voice notes you record for an alert (up to 60 seconds each); dialer actions.
- AI Assistant data: the messages you write and the photos you attach in each conversation, and the generated replies.
- Onboarding survey (before an Account exists): name, e-mail, language, time zone, the Care Recipient’s name and relationship, care mode, living distance, your worries and health focus, approximate number of medications, family size, the name you gave the Family Space and the initial care activities, measurements and schedule you selected.
- Device and technical data: Expo push token, platform (iOS/Android), session identifiers, time of last activity, IP address, request path and method, timestamps, error information. We do not collect advertising identifiers, precise device fingerprints or background location.
- Support data: the content of your e-mails to us and the address you write from.
- Purchase data: paid plans are not yet offered. If we introduce them, Apple or Google would send us only the information needed to verify your entitlement (such as a transaction or subscription identifier, product, period and status), and we will update this Policy before enabling purchases. We never receive your card or bank details.
4. Information about other people
KinPulse exists to care for others, so you will often enter data about a parent, partner, child or another relative, and about emergency contacts. You may do so only if you have a lawful basis: the person has agreed, or you are their parent, legal guardian or otherwise lawfully responsible for their care. For children under 14 in Spain (or the age set by the law of your country), the consent of a parent or guardian is required.
Where the law requires it, you are responsible for informing the people whose data you enter that KinPulse is used, what is recorded and with whom it is shared; you may point them to this Policy. If a person asks you to stop, you must remove their data or stop sharing it. Any person whose data is recorded in KinPulse can also contact us directly to exercise their rights; we may need the help of the user who entered the data to identify the records.
5. Information for people whose data is recorded by a relative
If you are a Care Recipient, family member or emergency contact and did not create a KinPulse Account yourself, your data was provided by the KinPulse user who cares for you or added you. We process it only on that user’s instructions and for the purposes described in this Policy; it is never used for advertising or sold. You may ask us at any time what is recorded about you, request its correction or deletion, or object to the processing, by writing to [email protected]; we answer within one month and may need the help of the user who entered the data to identify the records. You may also ask that user directly to remove your data or stop sharing it.
6. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases under Article 6 (and, for health data, Article 9) of the GDPR:
- Creating and managing your Account, authenticating you, keeping sessions, resetting passwords and sending security notifications — performance of the contract with you (Art. 6(1)(b)).
- Recording, storing, displaying and synchronising Care Data and sharing it within the Family Spaces you choose — performance of the contract (Art. 6(1)(b)) and, because this includes health data, your explicit consent (Art. 9(2)(a)), given when you enter health information into the App or share it. You may withdraw consent at any time by deleting the data or your Account.
- Sending care reminders and SOS alerts to the devices and members you select — performance of the contract (Art. 6(1)(b)). You control these features through the in-app settings and the notification and location permissions of your device.
- Providing the AI Assistant — performance of the contract (Art. 6(1)(b)); where you choose to include health or other special-category information in a message or photo, your explicit consent (Art. 9(2)(a)), given by sending that message.
- Processing the onboarding survey to prepare a starter plan and to contact you about the Service you requested — steps prior to a contract at your request (Art. 6(1)(b)) and your explicit consent for any health-related answers (Art. 9(2)(a)).
- If paid plans are introduced: verifying Store subscriptions and entitlements — performance of the contract (Art. 6(1)(b)).
- Securing the Service, preventing abuse, rate limiting, logging, debugging and backups — our legitimate interest in operating a secure and reliable service (Art. 6(1)(f)). We do not use health data for this purpose beyond what is strictly necessary to store and protect it.
- Responding to your requests and support e-mails — performance of the contract or our legitimate interest in answering you (Art. 6(1)(b) and (f)).
- Complying with legal obligations, such as tax, accounting and consumer law, and responding to lawful requests of public authorities — legal obligation (Art. 6(1)(c)).
- Establishing, exercising or defending legal claims — our legitimate interest (Art. 6(1)(f)) and Art. 9(2)(f) where health data is involved.
- Informing you about important changes to the Service or these documents — performance of the contract and legal obligation. We send commercial communications only with your prior consent or, to existing customers, about our own similar services, always identified as advertising and with a free opt-out link (LSSI-CE, Articles 20 and 21); you may object at any time.
7. Health data and other special categories
Care Data is health data within the meaning of Article 9 of the GDPR, and free-text entries may reveal other sensitive information. We process this data only because you choose to record it in order to organise care, only to provide the features you use, and only on the basis of explicit consent (or, for a Care Recipient, the consent or lawful authority obtained by you). You are never required to enter health data to hold an Account; features that do not need it continue to work without it.
When you create your Account, and before you first record health information, the App asks you to confirm separately that you consent to the processing of the health information you record, including about the persons you care for, and that the person concerned has agreed or that you are their parent, guardian or legal representative. We keep a record of this confirmation. You can withdraw it at any time by deleting the data or your Account.
We never use health data for advertising, profiling for marketing, credit or insurance purposes, or to train artificial-intelligence models, and we never sell it. Access on our side is limited to what is strictly necessary to operate, secure and support the Service and is protected by authentication and role-based access controls.
You can withdraw consent at any time by deleting individual entries, conversations or Care Recipients, by revoking sharing or by deleting your Account. Withdrawal does not affect processing that took place before it.
8. AI Assistant
When you use the AI Assistant, the 20 most recent messages of the conversation and up to the 3 most recent photos attached to them are sent from our server to OpenAI, L.L.C. (United States), which generates the reply through the OpenAI API using a model of the GPT-5 family (currently gpt-5.6-terra; the exact model may change). We call the API with response storage disabled and under OpenAI’s API data-usage terms, which provide that API content is not used to train OpenAI models and is retained by OpenAI for up to 30 days solely for abuse monitoring and legal compliance. The transfer to the United States is covered by the safeguards described under “International transfers”.
Currently the AI Assistant has no access to your Care Data, Family Spaces or Account; it sees only what you type or attach in that conversation. If we ever allow it to use your Care Data, we will ask for your separate consent first. Conversations are private to your Account and are not visible to your family. Photos attached to conversations are stored in Cloudinary with authenticated access. You can delete any conversation at any time, which also deletes its photos from our systems; conversations are also deleted with your Account.
The AI Assistant makes no decision with legal or similarly significant effect on you. Its answers are general information that you must verify with a qualified professional.
9. Who receives your data
We do not sell or rent personal data and do not share it with advertisers or data brokers. Personal data is disclosed only as follows:
- Members of your Family Spaces: according to the roles and sharing settings you choose. SOS alerts include your name, the Family Space name, your location link and voice notes. If a family member opens the location link, Google (Maps) receives the coordinates under Google’s own privacy policy. Care-reminder notifications sent through Apple, Google and Expo contain only a neutral text without medication names or health details; SOS notifications contain the sender’s name, the Family Space name and the location link.
- Processors acting on our instructions under data-processing agreements: Hetzner Online GmbH (Germany) — servers and database hosting; OpenAI, L.L.C. (USA) — AI model for the AI Assistant; Cloudinary Ltd. (Israel/USA) — storage of profile photos and AI chat photos; Expo (650 Industries, Inc., USA) — build tooling and push-notification relay to Apple and Google; Brevo (Sendinblue SAS, France) — transactional e-mail such as password-reset codes; Cloudflare, Inc. (USA) — DNS for our domain. Apple (Apple Inc. and, for users in the EU, Apple Distribution International Ltd., Ireland) and Google (Google LLC and, for users in the EU, Google Ireland Ltd. / Google Commerce Ltd.) deliver push notifications to your device and process Store purchases as independent controllers under their own policies. On Android, push notifications are delivered through Firebase Cloud Messaging, which is used solely for that purpose.
- Public authorities, courts or law enforcement: when required by law or a binding request, or to protect the rights, safety or property of a user, a Care Recipient, the public or us.
- A successor: if the Service is transferred to another operator, your data may be transferred under the same protections, and you will be informed in advance.
- Professional advisers (for example a lawyer or accountant) bound by confidentiality, only when necessary.
10. International transfers
Our servers and database are located in the European Union (Germany). Some providers process data outside the European Economic Area, under the following safeguards:
You may request a copy of the relevant safeguards at our contact address. We keep Standard Contractual Clauses in place with United States providers in addition to Data Privacy Framework certification, so that transfers remain lawful if the Framework is invalidated.
- OpenAI, L.L.C. (USA) — AI model: EU–US Data Privacy Framework and the Standard Contractual Clauses (Commission Decision 2021/914) included in OpenAI’s Data Processing Addendum.
- Cloudinary Ltd. (Israel) and Cloudinary, Inc. (USA) — image storage: European Commission adequacy decision for Israel (2011/61/EU) and EU–US Data Privacy Framework certification.
- 650 Industries, Inc. (Expo, USA) — push-notification relay and build tooling: EU–US Data Privacy Framework certification and Standard Contractual Clauses.
- Cloudflare, Inc. (USA) — DNS: EU–US Data Privacy Framework certification and Standard Contractual Clauses.
- Apple and Google — push delivery and Store purchases: their own transfer mechanisms as independent controllers.
11. How long we keep data
We keep personal data only for as long as needed for the purposes above and then delete or anonymise it:
- Account and Care Data: for as long as your Account exists. When you delete your Account, deletion starts immediately and the background clean-up of database records and files is normally completed within days. We keep no routine database backups beyond short-lived operational snapshots; any backup copy is deleted or overwritten within 30 days.
- Care Data in a shared Family Space that you created and that other members still use: remains available to them after you leave or delete your Account, with your authorship anonymised.
- AI conversations and photos: until you delete the conversation or your Account.
- SOS alerts, including location, call log and voice notes: kept in the Family Space’s alert history so that members can review past alerts, until the member who raised them deletes their Account; you may ask us to delete individual alerts earlier.
- Sessions and refresh tokens: 30 days after sign-in (refreshing does not extend them), or until you sign out, change your password or delete your Account. Invitation codes: 7 days. Password-reset codes: 10 minutes (at most 3 requests per 24 hours). Push tokens: until the session ends or you disable notifications.
- Onboarding survey submissions without an Account: no longer than 12 months from submission, or earlier at your request.
- Rate-limit counters: a few minutes. Server request logs: kept only for security and troubleshooting, no longer than 90 days, unless needed to investigate a security incident.
- Support e-mails: up to 24 months after the last exchange.
- If paid plans are introduced: Store transaction identifiers for the duration of the subscription and, where required by Spanish tax and commercial law, up to 6 years.
- Data needed to establish, exercise or defend legal claims: for the applicable limitation period.
12. Security
We apply technical and organisational measures appropriate to the sensitivity of health data: encryption in transit (TLS) for all connections; passwords stored only as salted hashes; short-lived access tokens and rotating refresh tokens kept in the device’s secure storage; role-based access to Family Spaces; authenticated access to stored photos; firewalls and restricted administrative access; regular updates; and systems designed so that application secrets stay on the server and server logs do not contain the content of Care Data. Your device also stores settings and SOS information locally; protect it with a passcode and keep your operating system updated.
No system is completely secure. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will, where required by law, notify the competent supervisory authority within 72 hours of becoming aware of it and inform you without undue delay.
13. Your rights
Under the GDPR and the LOPDGDD you have the right to:
- access your personal data and obtain a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”), subject to legal retention duties;
- restrict processing in the circumstances provided by law;
- receive the data you provided in a structured, commonly used, machine-readable format (we provide it as JSON on request by e-mail) and have it transmitted to another controller where technically feasible (portability);
- object to processing based on our legitimate interests;
- withdraw consent at any time, without affecting earlier processing;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not make such decisions);
- lodge a complaint with a supervisory authority, in particular the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain, www.aepd.es, or the authority of the EU country where you live or work;
- as heir or person designated by a deceased user or Care Recipient, request access to, rectification or erasure of their data (LOPDGDD, Article 3), unless the deceased prohibited it.
14. How to exercise your rights
Many rights can be exercised directly in the App: edit your profile, edit or delete Care Data, delete AI conversations, manage sharing and members, and delete your Account (Profile → Delete account). For anything else, e-mail [email protected] from the address linked to your Account with the subject “Privacy request”. To protect your data we may ask you to confirm your identity, for example by replying from the Account e-mail or confirming details that only the Account holder would know. We respond within one month; this period may be extended by two further months for complex requests, in which case we will tell you. Requests are free of charge unless they are manifestly unfounded or excessive.
15. Children
KinPulse Accounts are for adults aged 18 or over. We do not knowingly collect personal data from children as Account holders. Children may be recorded as Care Recipients only by a parent or legal guardian. If you believe a child holds an Account or that a child’s data has been recorded without proper authority, contact us and we will delete it.
16. Website visitors
The Website is informational. It sets no cookies of its own, uses no analytics, advertising or social-media trackers and contains no forms that submit data to us. When you load a page, our hosting and network providers receive the technical data necessary to deliver it (IP address, requested URL, browser type, time) and may keep short-term security logs. Language is chosen through the URL (/en, /uk, /es) without storing a preference. See the Cookie Policy for details.
17. Device permissions and notifications
The App asks for permissions only when a feature needs them: notifications (reminders and SOS), location (a single reading when you send an SOS), camera and photo library (profile photo and AI chat photos) and microphone (SOS voice notes). You can change permissions at any time in your device settings; refusing a permission limits only the related feature. The App does not request access to your contacts, calendar, health platforms (such as Apple Health or Google Fit) or background location, and does not use the Apple App Tracking Transparency framework because it performs no tracking.
18. Changes to this Policy
We may update this Policy when the Service, our providers or the law change. The current version with its effective date is always available on the Website. For material changes we will inform you in the App or by e-mail at least 15 days before they take effect, and where a change requires new consent we will ask for it.
19. Contact
Controller: Tsupylo Vitalii, Spain. E-mail: [email protected]. Supervisory authority: Agencia Española de Protección de Datos, www.aepd.es.